<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic TCP Reset-I while trying to do LDAP auth in AAA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/tcp-reset-i-while-trying-to-do-ldap-auth-in-aaa/m-p/1916039#M437148</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try to run "debug ldap" and see if it gives you more information.&lt;/P&gt;&lt;P&gt;From the packet capture, it seems that the 3 way handshake is succesfull, so TCP wise is OK. Seems to be more ldap problem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 13 May 2012 09:42:12 GMT</pubDate>
    <dc:creator>Jennifer Halim</dc:creator>
    <dc:date>2012-05-13T09:42:12Z</dc:date>
    <item>
      <title>TCP Reset-I while trying to do LDAP auth in AAA</title>
      <link>https://community.cisco.com/t5/network-security/tcp-reset-i-while-trying-to-do-ldap-auth-in-aaa/m-p/1916038#M437139</link>
      <description>&lt;P&gt;Short story, for a remote access VPN, i'm trying to auth against an ldap server on the outside of my branch office.&amp;nbsp; The branch office has an ASA 5505 sec plus.&amp;nbsp; The LDAAP server is in a data center behind a 5520, though it is statically nated to an external IP address.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I try and test auth against my ldap server though, I get an error saying that the ldap server id not respond.&amp;nbsp; however, I can see a tcp reset on the asa, and have captured some packets:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TCP reset:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Teardown TCP connection xxx for outside ldap.ldap.ldap.ldap/389 to identity:asa.asa.asa.asa/2807 duration 0:00:21 bytes 286 TCP Reset-I&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Packet Capture:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show cap capout&lt;/P&gt;&lt;P&gt;12 packets captured&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; 1: 13:00:11.836214 802.1Q vlan#2 P0 ASA.ASA.ASA.ASA.2807 &amp;gt; LDAP.LDAP.LDAP.LDAP.389: S 2552064091:2552064091(0) win 8192 &amp;lt;mss 1380,sackOK,nop,nop,nop,nop,timestamp 539401482 263829745&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 2: 13:00:11.853532 802.1Q vlan#2 P0 LDAP.LDAP.LDAP.LDAP.389 &amp;gt; ASA.ASA.ASA.ASA.2807: S 830582830:830582830(0) ack 2552064092 win 8192 &amp;lt;mss 1380,sackOK,timestamp 263895589 539401482&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 3: 13:00:11.853624 802.1Q vlan#2 P0 ASA.ASA.ASA.ASA.2807 &amp;gt; LDAP.LDAP.LDAP.LDAP.389: . ack 830582831 win 8192 &amp;lt;nop,nop,timestamp 539401499 263895589&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 4: 13:00:11.853776 802.1Q vlan#2 P0 ASA.ASA.ASA.ASA.2807 &amp;gt; LDAP.LDAP.LDAP.LDAP.389: P 2552064092:2552064237(145) ack 830582831 win 8192 &amp;lt;nop,nop,timestamp 539401500 263895589&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 5: 13:00:11.877853 802.1Q vlan#2 P0 LDAP.LDAP.LDAP.LDAP.389 &amp;gt; ASA.ASA.ASA.ASA.2807: P 830582831:830583323(492) ack 2552064237 win 64296 &amp;lt;nop,nop,timestamp 263895591 539401500&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 6: 13:00:11.877914 802.1Q vlan#2 P0 ASA.ASA.ASA.ASA.2807 &amp;gt; LDAP.LDAP.LDAP.LDAP.389: . ack 830583323 win 8192 &amp;lt;nop,nop,timestamp 539401524 263895591&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 7: 13:00:11.878311 802.1Q vlan#2 P0 ASA.ASA.ASA.ASA.2807 &amp;gt; LDAP.LDAP.LDAP.LDAP.389: P 2552064237:2552064304(67) ack 830583323 win 8192 &amp;lt;nop,nop,timestamp 539401524 263895591&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 8: 13:00:11.999109 802.1Q vlan#2 P0 LDAP.LDAP.LDAP.LDAP.389 &amp;gt; ASA.ASA.ASA.ASA.2807: P 830583323:830583433(110) ack 2552064304 win 64229 &amp;lt;nop,nop,timestamp 263895603 539401524&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 9: 13:00:11.999185 802.1Q vlan#2 P0 ASA.ASA.ASA.ASA.2807 &amp;gt; LDAP.LDAP.LDAP.LDAP.389: . ack 830583433 win 8192 &amp;lt;nop,nop,timestamp 539401645 263895603&amp;gt;&lt;BR /&gt;&amp;nbsp; 10: 13:00:11.999444 802.1Q vlan#2 P0 ASA.ASA.ASA.ASA.2807 &amp;gt; LDAP.LDAP.LDAP.LDAP.389: P 2552064304:2552064311(7) ack 830583433 win 8192 &amp;lt;nop,nop,timestamp 539401645 263895603&amp;gt;&lt;BR /&gt;&amp;nbsp; 11: 13:00:11.999551 802.1Q vlan#2 P0 ASA.ASA.ASA.ASA.2807 &amp;gt; LDAP.LDAP.LDAP.LDAP.389: FP 2552064311:2552064311(0) ack 830583433 win 8192 &amp;lt;nop,nop,timestamp 539401645 263895603&amp;gt;&lt;BR /&gt;&amp;nbsp; 12: 13:00:12.019103 802.1Q vlan#2 P0 LDAP.LDAP.LDAP.LDAP.389 &amp;gt; ASA.ASA.ASA.ASA.2807: R 830583433:830583433(0) ack 2552064311 win 0&lt;BR /&gt;12 packets shown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know I'm querying over 389, I can switch to secure after I get this working(initially tried secure, but same results).&amp;nbsp; The asa.asa.asa.asa address is the external IP of the branch office 5505.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can someone help tell me what I'm looking at?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:06:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-reset-i-while-trying-to-do-ldap-auth-in-aaa/m-p/1916038#M437139</guid>
      <dc:creator>AdmShatan</dc:creator>
      <dc:date>2019-03-11T23:06:02Z</dc:date>
    </item>
    <item>
      <title>TCP Reset-I while trying to do LDAP auth in AAA</title>
      <link>https://community.cisco.com/t5/network-security/tcp-reset-i-while-trying-to-do-ldap-auth-in-aaa/m-p/1916039#M437148</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try to run "debug ldap" and see if it gives you more information.&lt;/P&gt;&lt;P&gt;From the packet capture, it seems that the 3 way handshake is succesfull, so TCP wise is OK. Seems to be more ldap problem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 13 May 2012 09:42:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-reset-i-while-trying-to-do-ldap-auth-in-aaa/m-p/1916039#M437148</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-05-13T09:42:12Z</dc:date>
    </item>
  </channel>
</rss>

